Security fixes are provided for the latest 0.1.x release.
Please do not open a public issue for a suspected vulnerability.
Use Report a vulnerability on the repository's Security tab to start a
private security advisory. Include the PostgreSQL and pgvector versions, a
minimal reproducer, and whether the issue can reach normal execution or
EXPLAIN ANALYZE.
The most important security invariant is that hypothetical indexes must never be injected into an executable plan.